Infrastructure Enhancement, PCN and Cloudflare Sureroute Access
000003006
794
07/12/2024 15:40 PM
25.0
Answer
Infrastructure Enhancement: PCN and Cloudflare Sureroute Access
We have enhanced the performance and reliability of your transaction delivery over the Internet through the introduction of Cloudflare technology and upgrades to its public commercial network (PCN).
Current Schedule
CAS (Test)
Endpoint URL | Migrating to | PCN - Visa Data Center IP Address | |
OCC Central U.S. | OCE Eastern U.S. | ||
api.accountupdatertest.cybersource.com | PCN | 198.241.206.51 | 198.241.207.46 |
pnrtest.ic3.com | PCN | 198.241.206.83 | 198.241.207.92 |
ics2testa.ic3.com | PCN | 198.241.206.36 | 198.241.207.36 |
ics2wstesta.ic3.com | PCN | 198.241.206.37 | 198.241.207.37 |
testsecureacceptance.cybersource.com | Cloudflare | N/A* | N/A* |
testflex.cybersource.com | Cloudflare | N/A* | N/A* |
vacptest.visa.com | PCN | 198.241.206.37 | 198.241.207.37 |
businesscentertest.cybersource.com | Cloudflare | N/A* | N/A* |
Production
Endpoint URL | Migrating to | PCN - Visa Data Center IP Address | |
OCC Central U.S. | OCE Eastern U.S. | ||
api.accountupdater.cybersource.com | PCN | 198.241.206.48 | 198.241.207.52 |
pnr.ic3.com | PCN | 198.241.206.84 | 198.241.207.91 |
ics2a.ic3.com | PCN | 198.241.206.35 | 198.241.207.35 |
ics2wsa.ic3.com | PCN | 198.241.206.31 | 198.241.207.31 |
secureacceptance.cybersource.com | Cloudflare | N/A* | N/A* |
flex.cybersource.com | Cloudflare | N/A* | N/A* |
vacp.visa.com | PCN | 198.241.206.31 | 198.241.207.31 |
businesscenter.cybersource.com | Cloudflare | N/A* | N/A* |
Note:
- There will be no changes to any other endpoints not listed in the above tables.
- There is no specific IP address for endpoints listed as N/A*. At any given moment, a request across the Cloudflare network may route through any one of their thousands of IP addresses.
How to adopt the change
Merchants already using endpoints (listed in the table above) must do the following:
For Endpoints Migrating to PCN (see table above)
- Verify that all necessary SSL trust stores include three root-level SSL certificates.These root-level SSL certificates are provided by Entrust and can be found attached to this Knowledge Base article. Import them into your client app trust store.
- Verify that your infrastructure/network/firewalls white-list their outbound traffic with the new IP addresses listed in the above table.
For Endpoints Migrating to Cloudflare (see table above)
If you access these specific endpoints via web browsers, no change is required. The CERT for CloudFlare is already present in all major browsers.
if you access these endpoints via server-to-server communication, you must import/install Cloudflare SSL certificates available as an attachment to article Secure Accetpance and FLEX SSL Certificates for Server-to-Server Connection in CloudFlare.
- Do not perform any 'outbound' IP-address whitelisting or blocking of any kind
- Use Domain Name System (DNS).
If your company uses third-party software that submits transactions for processing, consult with your software provider to make all necessary changes.
FAQs
Why are we introducing this change?
This technology enables seamless transaction routing between multiple data centers and helps safeguard against interruptions caused by issues beyond our direct control, such as Internet congestion, fiber cable cuts, malicious Internet activity, etc.
Will there be any change to the Endpoint URL Domain Name?
No, all URLs domain names listed in the above table will remain the same.
Why are there two IP addresses for each endpoint migrating to PCN?
Each PCN endpoint has two IP addresses: each points to a different data center. These IPs are active/active. In the case of an issue connecting to one Data Center, traffic will be switched and routed to the other IP (data center). We recommend that you white-list both IP addresses.
Will there be any change to the other endpoint URLs?
No, only the URLs listed in the two above tables are included in this change.
Note:
Was this article helpful?